Release Notes for Build 51.26 of NetScaler MAS 11.1 Release

Updated: February 3, 2017 | Release notes version: 1.0
This release notes document describes the enhancements and changes, lists the issues that are fixed, and specifies the issues that exist, for the NetScaler MAS release 11.1 Build 51.26. See Release history.
Notes:
What's New?
The enhancements and changes that are available in Build 51.26.
Analytics
  • View start and end time of a terminated user sessions in Gateway Insight
    The start time and end time of a terminated user sessions in Gateway Insight are now shown in a session-details graph at Analytics > Gateway Insight > Users. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/mas-gateway-insight.html
    [# 649009]
  • Export Reports in Gateway Insight
    From NetScaler MAS, you can now save the Gateway Insight reports with all the details shown in the GUI in PDF, JPEG, PNG, or CSV format on your local computer. You can also schedule the export of the reports to specified email addresses at various intervals. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/mas-gateway-insight.html
    [# 631820]
  • Ability to view the details of failed EPA expressions in Gateway Insight
    The details of failed EPA expressions now appear in a table under the dashboard graph when you navigate to Analytics > Gateway Insight. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/mas-gateway-insight.html
    [# 606882]
  • View Authorization Policy Failures in Gateway Insight
    You can now view authorization errors that occurred after the authentication process. The authorization process determines whether the user has the authority to access certain features, or make changes in the application. For example, if users are restricted to using only few modules of the application, accessing other modules results in authorization errors. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/mas-gateway-insight.html
    [# 578024]
  • Ability to Export Reports in Security Insight
    From NetScaler MAS, you can now save the Security Insight reports with all the details shown in the GUI in PDF, JPEG, PNG, or CSV format on your local computer. You can also schedule the export of the reports to specified email addresses at various intervals. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/security-insight.html
    [# 636398]
  • Ability to Set Thresholds and Monitor Breaches in Security Insight
    You can now set thresholds for the safety-index and threat-index and monitor breaches of the thresholds.
    To set a threshold
    1. Navigate to System > Analytics Settings > Thresholds, and select Add.
    2. Select the traffic type as Security in the Traffic Type field, and enter required information in the other appropriate fields, such as Name, Duration, and Entity.
    3. In the Rule section, use the Metric, Comparator, and Value fields to set a threshold.
    For example, "Threat Index" ">" "5"
    4. Click Create.
    To view the threshold breaches, navigate to Analytics > Security Insight > Devices, and
    select the NetScaler instance. On the screen that appears, in the Application section, the Threshold Breach column shows the number of threshold breaches that occurred for each virtual server. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/security-insight.html
    [# 636397]
  • Ability to Search for Virtual Servers while Configuring Insight
    If you have a large number of virtual servers configured on a NetScaler instance, while enabling or disabling insight it might be difficult to locate a specific virtual server. You can now search for a virtual server in the application list of a NetScaler instance in NetScaler MAS.
    To search for a virtual server
    1. Navigate to Infrastructure > Instances, and select the NetScaler instance you want to enable AppFlow.
    2. From the Action drop-down, select Enable/Disable AppFlow.
    3. In the Application List section, select the type of Virtual server.
    4. Click Search, and specify the name of the virtual server. Click Refine Search.
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/analytics-how-to-articles/how-to-enable-analytics-on-instances.html
    [# 651885]
  • SSL Insight
    SSL Insight provides integrated, real-time monitoring of secure web transactions (HTTPS) for all the secure web applications being served by the NetScaler ADC. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/ssl-insight.html
    [# 660016]
  • Ability to Display HA Failover Time Information in NetScaler MAS Analytics
    When NetScaler HA failover happens and a reconnect occurs by using session reliability, NetScaler MAS displays the count of the HA failover per ICA session. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/HDX-Insight.html
    [# 644975]
  • Ability to View Graphs on Attacks on the Security Insight Dashboard
    On the security insight dashboard, you can now view graphs depicting total attacks on an instance.
    To view these graphs
    1. Navigate to Analytics > Security Insight > Devices, and select the NetScaler instance.
    2. In the Application section, click the arrow button next to the Total Attacks summary bar.
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/security-insight.html
    [# 636392]
  • Ability to View Additional User Metrics in HDX Insight
    HDX Insight now displays additional user metrics, such as WAN jitter and Server Side Retransmits. To view these metrics, navigate to Analytics > HDX Insight > Users, and select a user name. The user metrics appear in the table next to the graph. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/HDX-Insight.html
    [# 659103]
  • TCP Insight
    The TCP Insight feature of the NetScaler Management and Analytics System (NetScaler MAS) provides an easy and scalable solution for monitoring the metrics of the optimization techniques and congestion control strategies (algorithms) used in NetScaler ADCs to avoid network congestion in data transmission.
    By observing the key Transport Layer metrics, such as Data Volume, Throughput, and Speed, you can measure the traffic volume served by the ADC and evaluate the effectiveness of the TCP optimization. In the display, the metrics are broken down by stream Direction (from client to NetScaler and NetScaler to origin server), TCP Port, and Virtual LAN. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/tcp-insight.html
    [# 654077]
Application Management
  • Ability to Display all Services and Service Groups for Each Application Group
    On the Application Dashboard page, for each application, NetScaler MAS now displays all the services and service groups associated with the NetScaler instances that belong to that application. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/how-to-create-application-definition.html.
    [# 657552]
  • Ability to Select NetScaler Gateway Virtual Server during Application Definition
    You can now select the NetScaler Gateway virtual server while defining an application. NetScaler MAS supports the following types of virtual servers:
    - Load balancing virtual servers
    - Content switching virtual servers
    - GSLB virtual servers
    - NetScaler Gateway virtual servers
    - Cache redirection virtual servers
    - Authentication virtual servers
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/how-to-create-application-definition.html.
    [# 654175]
  • NetScaler MAS Application Dashboard Enhancements
    The following enhancements have been made to the Application Dashboard:
    1. Each application now displays the number of bound services, service groups, and servers.
    2. You can now click on the one-line displays in each application to enable or disable the bound services, service groups, and servers.
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/how-to-create-application-definition.html.
    [# 658524]
  • Ability to View Bound Entities when Multiple Objects are Selected in NetScaler MAS
    NetScaler MAS now provides the option to select multiple virtual servers, services, or service groups. You can see bound services and service groups, virtual servers, or services for all multiple objects that you have selected. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/how-to-create-application-definition.html.
    [# 658287]
Infrastructure
  • Ability to Monitor SSL Protocols Enabled with Enterprise Policy on the NetScaler MAS SSL Dashboard
    The NetScaler MAS SSL Dashboard now shows the distribution of SSL protocols that are running on your virtual servers. As an administrator, you can specify the protocols that you want to monitor through the SSL policy. The protocols supported are SSLv2, SSLv3, TLS1.0, TLS1.1, and TLS1.2. The SSL protocols used on virtual servers appear in a bar chart format. Clicking on a specific protocol displays a list of virtual servers using that protocol.
    A donut chart appears after Diffie-Hellman (DH) or Ephermeral RSA keys are enabled or disabled on the SSL dashboard. These keys enable secure communication with export clients even if the server certificate does not support export clients, as in the case of a 1024-bit certificate. Clicking on the appropriate chart displays a list of the virtual servers on which DH or Ephemeral RSA keys are enabled.
    [# 653408]
  • Ability to Preview a New Job Before Execution
    You can now evaluate and verify the commands to be run on each instance or instance group before you run a job. Previously, the information you would need was available only in the execution logs, which are not available until the job is executed. NetScaler MAS now has a Job Preview feature, which is available when you configure a job.
    [# 654179]
  • Ability to Define Global, Group, or Instance Level Variables
    You can now make edits to the global, group, and instance level variable values in the Input Key File while creating a job. Global variables are variable values that will be applied across all instances and instance groups in the event that those values are not provided. Group and instance level variable values are applied to all instances that are defined as variables in the job. In the file that is downloaded, you can provide variable values at instance level, instance group level, and global level. After downloading input key file, you can upload it to the NetScaler MAS server, and then execute the job with your customized variable values.
    [# 654178]
  • Ability to Create Configuration Jobs with Corrective Commands
    You can create audit templates with specific configurations that you want running on certain instances. NetScaler MAS compares these instances with the audit template and reports any mismatch in configuration. You can now correct the configuration commands being run on your NetScaler instance if there is a change in the configuration, to ensure optimal performance of your network. Using NetScaler MAS’s corrective commands feature, you can create an audit template with the modified and corrected configuration commands on specific NetScaler instances.
    When there is a difference between an instance's running and saved configurations, a Diff Exists status message appears on the Audit Report page. Clicking the Diff Exits link takes you to Configuration Diff page, where you can view the corrective command and create a job to run on that specific instance. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-create-configuration-jobs-from-corrective-commands-mas.html
    [# 654180]
  • Ability to Replicate Configuration Command from One NetScaler Instance to Another
    You can now replicate a NetScaler instance’s configuration on other instances. When you configure a job in NetScaler MAS, select an instance as the Configuration Source and choose the selected instance’s running or saved configuration. For example, when you select Running Configuration and click Extract, NetScaler MAS sends a request to the selected NetScaler instance to locate the running configuration, and displays it as a template. You can drag and drop the template into the Commands field in the right-hand pane. You can modify commands, parameters, and the instances. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-replicate-configuration-commands-from-one-netscaler-to-another-mas.html
    [# 654075]
  • Ability to Select Specific Event Severity on Infrastructure Dashboard
    On the Infrastructure Dashboard, you can now mask severity levels to more clearly display an event that you are interested in. To mask the levels that you don't want to appear on the severity graph, click them.
    For example, events of Critical severity level might occur rarely. However, when these critical events do occur on your network, you might want to further investigate them to troubleshoot and monitor where and when the event occurred. If you select all severity levels except Critical, the events severity graph shows only the critical events. You can then click the graph to go to a page that shows all the details of when a critical event occurred during the duration that you’ve selected, including the instance source, the date, category, and message notification sent when the critical event occurred. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/event-management-how-to-articles/how-to-display-event-severities-and-skews-of-SNM-traps-infrastructure-dashboard-mas.html.
    [# 654059]
  • Ability to Support '$' Symbol as a Variable while Performing the Copy-Paste Operation on the Create Job Commands Pane
    A value enclosed in dollar sign ($) symbols is automatically assumed to be a variable when it is copied to the Commands field while configuring a job. Previously, administrators had to select the value they wanted to convert to a variable, and then click "Convert to Variable." This is particularly useful when you are copying large sets of configuration commands with multiple variables.
    Note: You still have to define the variable.
    [# 654177]
  • Ability to Select a Previously Saved Configuration Template to Create an Audit Template
    In audit templates, you can now use configuration commands that were previously saved in configuration templates. While creating an audit template, you can drag and drop previously saved configuration templates into the Commands field, and edit the template to suit your requirements. You can also select specific instances on which to run these newly selected audit commands. NetScaler MAS compares these instances with the audit template and reports any mismatch. This helps you identify errors and rectify them in a timely manner.
    You can create configuration templates while creating a new job and saving a set of configuration commands as a template. When you save these templates on the Create Jobs page, they are automatically displayed on the Create Template page. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-use-configuration-templates-to-create-audit-templates-on-mas.html.
    [# 487693]
  • Ability to View Events Summary
    You can now view and monitor the events and traps received on your NetScaler MAS server. The Events Summary page displays the following information in a tabular format:
    - Summary of all the events received by NetScaler MAS. The events are listed by category, and the different severities are displayed in separate columns: Critical, Major, Minor, Warning, Clear, and Information.
    - Number of events received for each category. Clicking on the event displays the Events page, on which filters such as the Category and Severity are preselected, and which displays more information about the event, such as the NetScaler instance, host name, date when the event was received, category, and the message notification received.For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/event-management-how-to-articles/how-to-view-events-summary-in-mas.html
    [# 653877]
  • Support for Monitoring HAProxy Instances
    You can now use NetScaler MAS to monitor HAProxy instances in your deployment. To do so, navigate to Infrastructure > Instances > HAProxy.
    You can also navigate to Applications > Dashboard > HAProxy to view the servers, frontend, and backend configured on the HAProxy instances.
    For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/monitoring-haproxy-instances.html.
    [# 638608]
  • Ability to Represent Skews of SNMP Traps on Infrastructure Dashboard
    On the Infrastructure dashboard, you can now mask irrelevant values so that you can more easily view and monitor information such as health, up time, models, and version of NetScaler instances in minute detail.
    For example, when you view the health of a NetScaler VPX instance on the Infrastructure dashboard, you can mask all the times during which the instance was up and running, and view only the times the instance was 'out of service.' For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/event-management-how-to-articles/how-to-display-event-severities-and-skews-of-SNM-traps-infrastructure-dashboard-mas.html
    [# 654060]
Orchestration
  • Support for OpenStack Mitaka Features in NetScaler MAS
    NetScaler MAS now supports integration with OpenStack Mitaka, giving OpenStack users access to NetScaler capabilities from OpenStack.
    [# 605594]
  • Support for OpenStack Newton Features in NetScaler MAS
    NetScaler MAS now supports integration with OpenStack Newton. This enhancement enables integration with OpenStack Newton and gives OpenStack users access to NetScaler services from OpenStack.
    [# 646611]
  • Exposing advanced NetScaler Features through OpenStack Heat using NetScaler MAS
    In addition to being able to integrate OpenStack Neutron LBaaS, OpenStack users can now configure more advanced features of NetScaler through OpenStack Heat, by using StyleBooks provided in NetScaler MAS. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/integrating-netscaler-mas-with-openstack-platform/integrating_netscaler_mas_with_openstack_heat_services.html.
    [# 640110]
  • NetScaler MAS Orchestration User Interface Enhancements
    New organization of the Orchestration tab in NetScaler MAS shows the third-party services with which the NetScaler MAS integrates under three headings:
    - OpenStack and Accelerite cloud platforms are under "Cloud Orchestration."
    - Cisco ACI support and VMware NSX manager are under "SDN Orchestration."
    - Under "Container Orchestration," you can deploy your containerized applications and micro services with Mesos cluster management software.
    [# 653565]
  • Support for OpenStack L7 Switching Support in NetScaler MAS
    NetScaler MAS can now orchestrate the OpenStack Neutron Layer 7 (L7) switching functionalities by deploying them on NetScaler instances. When the L7 configurations are created in OpenStack with a NetScaler instance as the provider, NetScaler MAS allots a NetScaler instance, and deploys content switching and responder configurations corresponding to the L7 configurations. The NetScaler instances can then distribute and load balance user requests on the basis of application-layer characteristics of the requests. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/integrating-netscaler-mas-with-openstack-platform/configuring-layer7-content-switching-mas.html.
    [# 657952]
StyleBooks
  • Deploying StyleBook Configuration on Multiple NetScaler Instances
    You can now deploy a single StyleBooks configuration on multiple NetScaler instances.
    [# 662221]
  • Support for Nitro non-CRUD Operations in StyleBooks
    NetScaler MAS StyleBooks now supports Nitro non-CRUD operations such as "enable feature" and "enable mode." Add the "meta-properties" attribute in the Components section in the StyleBooks to enable the support.
    [# 656493]
System
  • Ability to Backup and Restore NetScaler MAS
    You can now configure a backup NetScaler MAS server that continuously archives your primary NetScaler MAS server's data to ensure minimum loss of data in the event that your system becomes unstable. Transaction logs are continuously synced from your primary server to the backup NetScaler MAS server. The entire database on the primary NetScaler MAS server is archived and transferred remotely to the backup server during a scheduled time. By default, it is done once every 15 days.
    This method of transferring your entire NetScaler MAS server’s database to a backup NetScaler MAS server is called “base backup.” For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/mas-system-how-to-articles/how-to-backup-and-restore-configuration-on-mas.html.
    [# 632373]
Fixed Issues
The issues that are addressed in Build 51.26.
Analytics
  • When you use LDAP for external authentication, you might receive a "Error: Resource does not exist" error message when you click the Configuration tab.
    [# 658344]
  • HDX insight in NetScaler MAS might display zero for ICA_RTT average.
    [# 660173]
  • If URL reporting is enabled, analytics subsystem might fail, and reports might not be displayed.
    [# 649947, 667326]
  • There is no option to select the gateway device in a multi-hop deployment for NetScaler MAS. This does not allow us to bifurcate and report client and server side latency correctly.
    [# 658855]
  • When Appflow is enabled for a new VPN virtual server through NetScaler MAS Analytics, the NetScaler MAS Analytics stops reporting ICA session data for some sessions.
    [# 644748, 643704]
Application Management
  • The Bound Service Group option was earlier displayed in both the Services and Virtual Servers pages in the NetScaler MAS GUI. Because there is no mapping from services to service groups, the redundant Bound Service Group option is removed from the Services page. You can now view bound service groups from the Virtual Servers page. Select multiple virtual servers to view all service groups bound to the virtual servers.
    [# 662245]
Infrastructure
  • Scheduled and manual backups of NetScaler SDX instances are unsuccessful when they are initiated on NetScaler MAS in high availability mode.
    [# 664945]
  • When NetScaler instances in a high availability setup are added to NetScaler MAS, duplicate certificates are displayed for these instances in NetScaler MAS because certificate polling is performed on both the primary and secondary NetScaler instances.
    [# 668709, 657647]
  • During each polling cycle, the identities of virtual IP addresses and services change. As a result, users are unable to use NITRO APIs to perform operations on NetScaler MAS.
    [# 667409]
  • Event reports might not be accurately displayed if you log on to NetScaler MAS with other than the default credentials (nsroot and nsroot).
    [# 667581]
  • API calls for servicegroup bindings on NetScaler MAS do not apply Role Based Access (RBA) accurately for service group members.
    [# 667783]
  • Event reports might not be visible to if you log on to NetScaler MAS with other than the default credentials (nsroot and nsroot).
    [# 665445, 665554]
  • NetScaler MAS crashes multiple times after a fresh install or if the NetScaler MAS server is upgraded.
    [# 668556, 668621, 671047]
  • In a NetScaler MAS high availability setup, certificates are not displayed accurately when certificate polling is enabled.
    [# 666955]
  • On the Licensing page of NetScaler MAS, host identities for a few NetScaler instances is displayed as "Unknown."
    [# 669472]
  • When you search for a virtual server (Applications > Load Balancing > Virtual Servers) by using your NetScaler MAS server’s IP address, the Search button is not visible after the first time you use it. To be able to see the Search button repeatedly, you have to access NetScaler MAS through its DNS alias.
    [# 665622]
  • When the same NetScaler instances are discovered by a standalone NetScaler MAS deployment and a NetScaler MAS high availability (HA) deployment, the HA deployment shows a larger number of virtual servers and services.
    [# 670072]
  • You cannot search for admin partitions by name on NetScaler VPX instances. You must search by IP address. With this fix, you can use the Host Name filter to search for admin partitions.
    [# 670570]
  • When you click the Learn More button while searching for an instance on the Infrastructure tab of NetScaler MAS, a “Page not found” error message appears. This typically occurs after you upgrade your NetScaler MAS version to 11.1 build 49.16.
    [# 664965]
  • When a failover occurs for a NetScaler instance in a high availability setup, entities that were enabled or disabled are not displayed on the NetScaler MAS GUI.
    [# 664067]
  • Event messages are not sorted accurately by date when you click on the Date tab in the Events Messages page.
    [# 670593]
  • The ns_servicegroupmember_binding resource is missing from the enable and disable functions in the NetScaler MAS server's SDKs.
    [# 670876]
  • In NetScaler MAS, the nssdx.py class is missing from the NITRO API SDK for Python.
    [# 662355]
  • Entity polling in NetScaler MAS stops because of database issues.
    [# 666954]
  • Database connection issues prevent NetScaler MAS reports from showing any data.
    [# 658589, 667592]
  • The SSL Certificates page of NetScaler MAS does not show the host names associated with the certificates. With this fix, you can see the Host Name associated with a certificate as a column in the SSL certificates page.
    [# 665130]
  • You can now view the serial number of a managed NetScaler SDX instance. To view the serial number, navigate to the Infrastructure > Instances > NetScaler SDX.
    [# 662180]
  • When creating configuration jobs in NetScaler MAS, you cannot copy and paste commands in the Commands editor. For example, if you type a command in the editor, copy the command and try to paste it in the next line, the command does not get pasted.
    [# 663486]
Orchestration
  • In OpenStack integration, the installation files and scripts in the NetScaler driver bundle, and the configurations in the neutron.conf file now display NetScaler MAS options.
    [# 653696]
  • If a network gets disconnected while you are autoprovisioning NetScaler instances on NOVA, you should not perform other operations on the NetScaler instances. Doing so could result in the instance becoming unstable. In that case, you might have to ask Citrix technical support to reconfigure the instance.
    [# 590687]
  • For NSX Integration, a VLAN is allotted for every VXLAN during service insertion. The VLANs do not get de-allotted when service insertion is disabled/deleted. Because of this VLANs might get exhausted.
    [# 648726]
StyleBooks
  • In the "Sample Application StyleBook using CS, LB and SSL features" (sample-cs-app) StyleBook, the name of the application is hard coded. Therefore, using this StyleBook you can create only one application configuration (config pack) from this StyleBook on the same target device. If you try to create a second configuration from this StyleBook, an error message is displayed mentioning that the resource already exists.
    [# 665099]
System
  • File sync issues between NetScaler MAS nodes can occur if bad permissions on a private key file disrupt the Secure Shell (SSH) channel between the nodes of a high availability pair.
    [# 664887]
  • When multiple NetScaler MAS servers access a NetScaler instance at the same time to back up the instance, backup files might get overwritten. To prevent this, a random string is now appended to the backup files.
    [# 658479]
  • Even if the email notification option is disabled when system-related functions are configured, the NetScaler MAS server sends emails.
    [# 665567]
Known Issues
The issues that exist in Build 51.26.
Analytics
  • Some graphs are missing from NetScaler MAS analytics reports. Also, pop-up errors were exported in the analytics reports.
    [# 670044]
  • In Security Insight, Safety Index filters display incorrect output.
    [# 640160]
  • In Security Insight, on the Application Summary page, IP reputation is not displayed in the Violation Category drop-down list.
    [# 643629]
  • In Security Insight, exported reports doesn't show the selected duration when exported in pdf, jpeg, or png format.
    [# 670341]
  • URL data collection is enabled by default on NetScaler instances but is not supported by Web Insight. As a result, the NetScaler MAS server might become unresponsive. Disabling URL data collection is recommended. In the NetScaler GUI, navigate to System > Analytics Settings > Configure Data Record Settings, and clear the Enable URL Data Collection check box.
    [# 671992]
  • For NetScaler SD-WAN, while using the "SetTrafficShapingPolicy" built-in template to execute Configuration jobs, you are required to specify values for all parameters, even if they are not mandatory.
    [# 613965, 613962]
  • In Security insight, Search option drop-down list for Application Summary does not include all the filters.
    [# 630031]
  • For NetScaler MAS in high availability mode, only Hourly reports are available. Daily, Monthly, and yearly reports are not available.
    [# 669904]
  • The time interval for which data is displayed on the dashboard might not match the selected time interval. If no data is available for part of the selected time interval, NetScaler MAS shows data from the date on which it started receiving the AppFlow data.
    [# 601474]
Infrastructure
  • The HAProxy instance dashboard displays incorrect color for CPU and memory usage.
    [# 671754]
  • NetScaler MAS responds slowly or fails to respond to input from the GUI when the NetScaler MAS server's database contains a large number of events.
    [# 670789]
  • After a failover occurs on a NetScaler instance in a high availability setup, data is not visible in the NetWork Interfaces table on that instance's dashboard in NetScaler MAS.
    [# 671368]
Licensing
  • NetScaler MAS randomly selects the virtual servers to monitor on the basis of your license. For example, if you have a license for 130 virtual servers, NetScaler MAS randomly selects 130 virtual servers to monitor. If you want to monitor a smaller number of virtual servers, you can deselect the virtual servers you do not want to monitor. These virtual servers become unlicensed, freeing up that number of licenses. However, the next time that NetScaler MAS polls, the unlicensed virtual servers are randomly added for monitoring, which uses up the available licenses.
    [# 658385]
Orchestration
  • Service instance runtime created on VMware NSX Manager supports one management interface and multiple data interface at the time of creation. But, you cannot edit the service instance to add another data interface.
    [# 668723]
  • In orchestration, when a NetScaler instance is unassigned from a service package, the interfaces configured for the instance are lost.
    Workaround: The interfaces should be reconfigured if the same NetScaler instance is assigned to another service package.
    [# 620635]
  • In NetScaler MAS, when you use the "New" widget to add tenants while creating a service package or assigning OpenStack tenants, you can add only one tenant at a time. If you add multiple tenants, only the first selected tenant will be assigned to the NetScaler instance.
    Workaround: Edit the service package. After you click the edit icon in the Configure OpenStack Tenants/Placement Policies section, the other tenants that you selected are available for assignment.
    [# 671235]
  • In orchestration, if you perform "Cleanup" operation for requests on which rollback failed, the following error message is displayed: "Rollback is not allowed for successfully completed requests".
    Workaround: You can refresh the page to view if the failed rollback has succeeded.
    [# 601294]
StyleBooks
  • The NetScaler MAS system upgrade process does not support APIC StyleBook. Although the config pack is successfully migrated, it cannot be updated.
    [# 667763]
System
  • In a NetScaler MAS high availability setup, when you make changes to the system settings on one node (System > System Administration > System Settings ), you must confirm the changed system settings on the secondary node by clicking OK, even if the GUI shows that the system settings have been applied.
    [# 669460]
  • NetScaler MAS restarts as soon as you apply the required Cipher group and click "OK" even before you click "Done". The NetScaler MAS should restart after you click "Done". Also, NetScaler MAS should display a confirmation pop-up message before the system restarts.
    [# 660805]
  • In a NetScaler MAS high availability setup, when you back up and restore the system, the instance backup settings (System > System Administration > Instance Backup Settings) do not get backed up and restored to the values that were set prior to taking the backup.
    [# 661049]
  • In NetScaler MAS, when you apply the required Cipher group to configure the SSL settings, the system selects the last created cipher group by default even when you apply any other group created previously. The system should select the group that was applied.
    [# 660799]
What's New in Previous NetScaler MAS 11.1 Releases
The enhancements and changes that were available in NetScaler MAS 11.1 releases prior to Build 51.26. The build number provided below the issue description indicates the build in which this enhancement or change was provided.
Analytics
  • X-Forwarded-For HTTP Header Support for Security Insight Reports
    The X-Forwarded-For HTTP header field is a common method for identifying the originating IP address of a client connecting to a web server through an HTTP proxy or load balancer. NetScaler MAS uses X-Forwarded-For HTTP header to obtain the following details:
    - The address of the client which connected to the proxy.
    - The content of the host header the client sent to the proxy.
    Currently X-Forwarded-For support is available only for Web Insight and Security Insight.
    Note: You can only enable or disable the X-Forwarded-For feature using the NetScaler appliance's CLI.
    To enable this feature, at the command prompt, type: "set appflow param httpXForwardedFor ENABLED".
    [From Build 49.16] [# 636390]
  • Comparing Graphs in NetScaler MAS Analytics
    You can now combine any two graphs in NetScaler MAS Analytics (Insight) to view and compare the selected parameters.
    [From Build 49.16] [# 617967, 593755]
  • Support to Migrate NetScaler Insight Center to NetScaler MAS
    You can now migrate your NetScaler Insight Center deployment to NetScaler MAS without losing the existing configuration, settings, or data in NetScaler Insight Center. With NetScaler MAS you can not only view the various analytics data generated by the NetScaler instances associated to an application, but you can also manage, monitor, and troubleshoot the entire global application delivery infrastructure from a single, unified console. Note that you can only migrate a standalone NetScaler Insight Center deployment to a standalone NetScaler MAS deployment. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/migrating-netscaler-insight-center-to-mas.html
    [From Build 49.16] [# 632967, 649903]
  • Support to Integrate NetScaler MAS with Citrix Director
    NetScaler MAS is now integrated with Citrix Director. This enables Director to display HDX Insight reports from NetScaler MAS in the Network and the User details page and provides has user, applications, desktops, instances and license specific information. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/integrating-netscaler-mas-with-drector.html.
    [From Build 49.16] [# 647135]
AppFlow
  • If a NetScaler high-availability failover occurs when ICA AppFlow is enabled, the session reliability feature will now restore the session. This capability is currently disabled by default and configurable via CLI. The CLI command to enable/disable the feature is
    set ica parameter EnableSRonHAFailover YES/NO
    [From Build 49.16] [# 456218, 438710, 547601, 620411]
Application Management
  • Using Regular Expressions to Configure Load Balancing Virtual Servers in NetScaler MAS
    When defining an application from Applications > Dashboard > Applications > New Application, you can now use regular expressions to select multiple virtual servers. For example, the owa|lync expression selects all virtual servers that contain "owa" or "lync" in their names.
    [From Build 49.16] [# 657447]
  • Editing the name of the application
    When you create an application (Applications > Dashboard > Applications), earlier there was no option to edit the name of the application. With this fix, you can edit the name of the application at any later time.
    [From Build 49.16] [# 644896]
  • Configuring Load Balancing Virtual Servers From the Application Dashboard
    You can configure load balancing virtual servers and bind or unbind services and service groups from the Application Dashboard screen of the NetScaler MAS. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/application-management-how-to-articles/load-balancing-support-through-application-dashboard.html.
    [From Build 49.16] [# 653169]
Infrastructure
  • Reusing Completed Configuration Jobs on NetScaler MAS
    You can now modify the commands, parameters, configuration settings, and instances in a completed or a scheduled job and execute the job again. This is useful when you want to execute the same set of commands on a different instance or when the job encounters an error and stops further execution. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-jobs-replicate-configuration.html.
    [From Build 49.16] [# 637401]
  • Wildcard Character Support for Failure Objects
    You can now use the wildcard character search for failure objects to apply to a rule. You can use * as a wildcard character in the Add field above the Failure Objects parameter in the Create Rule page, to search for similar failure objects that can be applied to the rule. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/event-management-how-to-articles/how-to-set-multiple-event-rules-notifications-mas.html.
    [From Build 49.16] [# 653144]
  • Unrecognized Failovers in NetScaler MAS
    Earlier when failover occurred on NetScaler instances in a high availability mode, NetScaler MAS was unable to detect the state change until the next polling by the system. Now, when failover occurs on NetScaler instances in a high availability mode, NetScaler MAS updates the primary or secondary node's state based on SNMP traps received by NetScaler MAS when the instance state changes.
    [From Build 49.16] [# 657297]
  • Support to View Host Names with IP Addresses of NetScaler Instances
    You can now view the host name along with the IP address of your NetScaler instance across all tables and graphs in NetScaler MAS. Previously, only the IP address was displayed, making it difficult to keep track of thousands of instances. By assigning host names, you can now identify instances more easily.
    [From Build 49.16] [# 649667]
  • View Instance User Information in Execution Logs
    Execution logs are generated when you create and execute a job that contains the NetScaler user (Instance User) whose credentials were used to perform the action. Previously, only the MAS user’s name was displayed in the execution log. In some cases, both the MAS user and the NetScaler user had the same system credentials, nsroot/ nsroot. In this situation, should your NetScaler profile be changed, you can rediscover the instance with its new user credentials and execute the job again. You can then see the new instance user credentials in the execution summary.
    To view execution logs with system and instance name, navigate to Infrastructure > Configuration Jobs. Select a job and click Details. Click Execution Summary to see the status of the instance on that executed the job and the instance user's name. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-create-configuration-job.html
    [From Build 49.16] [# 653167]
  • Support to Send Email Notifications when Jobs are Executed
    Email notifications can now be sent every time a job is executed or scheduled. The notifications provide information such as the success or failure of the job, and include relevant details. If you have created a job in NetScaler MAS to perform specific configuration changes on a NetScaler appliance, and you want to know if the scheduled task has succeeded or failed, you previously had to log back on to NetScaler MAS and check the execution logs. You can now direct NetScaler MAS to send an email reporting on the success or failure of the task. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/configuration-management-how-to-articles/how-to-create-configuration-job.html
    [From Build 49.16] [# 652828]
  • Email Notification Support to Send Configuration Audit Notifications for Saved v/s Running Config Differences
    You can now configure NetScaler MAS to send email notifications every time the saved configuration is different from the running configuration on managed NetScaler instances. A configuration might get changed when you manually poll your instances, or if you have scheduled a configuration to be run at a particular polling interval. For more information, see https://docs.citrix.com/en-us/netscaler-mas/11-1/nmas-audit-configuration-instance.html
    [From Build 49.16] [# 653168]
Licensing
  • Expiry Check Support for Virtual Server Licenses
    You can now view the status and set alerts for the virtual server licenses expiry in NetScaler MAS. This helps you plan your license upgrades on time. You can set the expiry notifications to be received through email or through SMS. To view the status of the licenses, navigate to Infrastructure > Licenses > System Licenses. Then, in the License Expiry Information section, you can find the details of the licenses that are going to expire. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/netscaler-mas-licensing.html
    [From Build 49.16] [# 649426, 660051]
  • Management and Monitoring Support for Virtual Servers through NetScaler MAS
    You can now select the virtual servers to manage and monitor through MAS. To manage licensed virtual servers, navigate to Infrastructure > Licenses > System Licenses, and select Modify Licensed Virtual Servers to license/un-license the virtual servers. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/netscaler-mas-licensing.html
    [From Build 49.16] [# 649425, 649591]
  • Port Configuration Support for License Server Client
    If your network firewall does not allow the using of ports above 10000 for communication between license server (port 27000) and NetScaler instances, you can use vendor daemon port (7279) for communication. For more information, see http://docs.citrix.com/en-us/netscaler-mas/11-1/netscaler-mas-licensing.html
    [From Build 49.16] [# 649424]
StyleBooks
  • StyleBooks for NITRO Entities Available on NetScaler MAS
    Built-in StyleBooks corresponding to all NITRO entities for releases 10.5, 11.0, and 11.1 are now available on NetScaler MAS. You cannot access these StyleBooks from the NetScaler MAS GUI. To access these built-in StyleBooks, you have to use StyleBooks API requests.
    For example, to get the definition of a built-in StyleBook for lbvserver resource of NetScaler NITRO API, you have to use the following GET request:
    [GET] http://<mas_ip>/stylebook/nitro/v1/config/stylebooks/netscaler.nitro.config/<netscaler_release>/lbvserver
    To create a load balancing virtual server on the target instance with the specified attribute values, you have to use the following POST request:
    [POST] http://<mas_ip>/stylebook/nitro/v1/config/stylebooks/netscaler.nitro.config/<netscaler_release>/lbvserver
    payload:
    {
    "configpack": {
    "parameters": {
    "name": "test-lb",
    "servicetype": "HTTP",
    "ipv46": "101.102.11.10",
    "port": 80
    },
    "target_devices": {
    "<device IP>": {
    "id": "<device_id>"
    }
    }
    }
    }
    For more information on how to use APIs to create configurations from StyleBooks, see: http://docs.citrix.com/en-us/netscaler-mas/11-1/stylebooks/how-to-use-api-to-create-configuration-from-stylebooks.html
    [From Build 49.16] [# 644498]
  • Support for File Uploads From StyleBooks by Using NetScaler MAS GUI
    To upload certificate file and certificate key file, two new types of parameters are now available, "certfile" and "keyfile". For these two parameter types, you can now upload the files directly from your local system when you are creating a StyleBook configuration using the NetScaler MAS GUI. The uploaded certificate file is stored in the directory /var/mps/tenants/<tenant_path>/ns_ssl_certs and the certificate key file is stored in /var/mps/tenants/<tenant_path>/ns_ssl_keys in NetScaler MAS. These uploaded certificates become part of the certificates managed by NetScaler MAS.
    For uploading any other type of file, you can use the parameter type "file". In this case, you have to first manually upload the file to /var/mps/tenants/<tenant_path>/ on NetScaler MAS, before you can use that file in a StyleBook configuration.
    When creating configurations from StyleBooks, you must provide only the name of the file you want to upload if you are using the API for any of the three parameters types or if the parameter type is "file" (from NetScaler MAS GUI or API). You must not provide the complete path of the files. The files are expected to be already available in the respective folders.
    [From Build 49.16] [# 645248]
  • Configure Alerts and Collect Analytics Data on a Virtual Server Defined by Using a StyleBook
    You can now use the operations construct in StyleBooks to configure NetScaler MAS analytics alarms on any virtual server created through the StyleBook. The attributes in this construct are used to set thresholds to generate alarms and send notifications on the virtual server. For example, you can configure an alert to send notification if the total requests handled by a load balancing virtual server is greater than 25 and for a period defined by the user. For more information, see: http://docs.citrix.com/en-us/netscaler-mas/11-1/stylebooks/how-to-enable-analytics-on-virtual-server-defined-in-stylebooks.html
    [From Build 49.16] [# 627838]
System
  • Compressing Core Files to Save Disk Space
    The NetScaler MAS server now compresses the backup files that are generated during the "backup and restore" process. This ensures that the backup files now occupy minimum storage within the server.
    [From Build 49.16] [# 654672]
Fixed Issues in Previous NetScaler MAS 11.1 Releases
The issues that were addressed in NetScaler MAS 11.1 releases prior to Build 51.26. The build number provided below the issue description indicates the build in which this issue was addressed.
Analytics
  • NetScaler Insight Center displays the VPN virtual server IP address in the Server IP Address field rather than the XenApp or XenDesktop server IP address.
    [From Build 49.16] [# 635525]
  • NetScaler MAS Analytics displays the HA failover count per ICA session whenever HA failover happens, and a reconnect occurs using session reliability.
    [From Build 49.16] [# 644975]
  • In a NetScaler MAS high availability setup, the Analytics configuration does not work.
    [From Build 49.16] [# 642270, 644542]
  • When you upgrade the NetScaler appliance from 11.0 release to a newer release (11.1 or higher), Security Insight is set to disabled.
    [From Build 49.16] [# 653626]
  • NetScaler MAS Analytics displays the NetScaler HA failover count per ICA session whenever HA failover happens, and a reconnect occurs using session reliability.
    [From Build 50.10] [# 644975]
  • If you add CloudBridge appliances in NetScaler MAS, Web Insight reports might not be displayed.
    [From Build 50.10] [# 659008]
  • Geo location does not resolve from Maxmind GeoCity.dat database file.
    [From Build 50.10] [# 656017]
  • When you use LDAP for external authentication, you might receive a "Error: Resource does not exist" error message when you click the Configuration tab.
    [From Build 50.10] [# 658344]
  • If URL reporting is enabled, analytics subsystem might fail, and reports might not be displayed.
    [From Build 50.10] [# 649947]
  • For a NetScaler appliance in multicore setup, reports from all cores were not getting generated except "0" core.
    [From Build 50.10] [# 656225]
  • The value of the X-Forwarded-For HTTP header field is not displayed as client IP address in Security Insight violation logs.
    [From Build 50.10] [# 645284, 636390]
  • When you upgrade the NetScaler appliance from 11.0 release to a newer release (11.1 or higher), Security Insight is disabled.
    [From Build 50.10] [# 653626]
AppFlow
  • If Appflow for ICA is enabled on a NetScaler appliance, the appliance might become unresponsive under certain circumstances during ICA capability negotiation in ICA PROXY mode.
    [From Build 49.16] [# 653385, 655823]
  • If HDX insight is enabled on a NetScaler appliances in high availability mode, and if the nodes are set to STAY PRIMARY or STAY SECONDARY, session reliability fails when a failover happens.
    [From Build 49.16] [# 653438]
  • When AppFlow for ICA is enabled on a NetScaler appliance in a multi core environment, the Netscaler appliance might become unresponsive.
    [From Build 49.16] [# 647713]
  • Automatic client reconnection (ACR) for Linux VDA clients fails if the NetScaler appliance is in the path and ICA AppFlow is enabled for the appliance.
    [From Build 50.10] [# 648254]
  • If the NetScaler appliance sends AppFlow data with application firewall records to NetScaler MAS, the appliance might fail. This might occur if the built-in NOPOLICY policy, which does not have any specified action, is configured as a global policy.
    [From Build 50.10] [# 656771]
Infrastructure
  • If the frequency of a job is scheduled as "once" for a specific time and date, the job is executed immediately instead of getting executed at the scheduled time.
    [From Build 49.16] [# 654763]
  • If the frequency of a job is scheduled as "once" for a specific time and date, the job is executed immediately instead of getting executed at the scheduled time.
    [From Build 50.10] [# 654763]
NS-MAS
  • In NetScaler MAS, virtual servers and services takes a long time (~30 minutes) to be discovered on a HA setup.
    [From Build 48.10] [# 647904]
  • The Desktop Director is not integrated with the NetScaler MAS.
    [From Build 48.10] [# 647135]
  • Events and syslog data are not sorted by date in the NetScaler MAS GUI.
    [From Build 48.10] [# 647576]
  • During instance interface configuration for Orchestration, the user can disable/enable the interface or assign the VLAN range. After user updates the setting, the GUI does not display the updated settings, until the page is refreshed.
    [From Build 48.10] [# 648363]
  • NetScaler MAS NITRO API documentation references "NetScaler SDX" instead of "NetScaler MAS".
    [From Build 48.10] [# 647686]
  • The Tasks page under the Request tab keeps refreshing even after the tasks are complete.
    [From Build 48.10] [# 647517]
  • Using the NetScaler MAS GUI, you might not be able to delete partitioned instances that have gone out of service.
    [From Build 48.10] [# 644750]
  • Enabling or disabling an entity from the Application Dashboard by using the State On-Off button does not create audit logs.
    [From Build 48.10] [# 646015]
  • For a service pack with an auto-provisioned device, NetScaler MAS does not support an HA pair for NOVA.
    [From Build 48.10] [# 648298]
  • After selecting one of the Cloud Platforms and submitting the form with the required settings under Orchestration, you is redirected to the Cloud Platform Selection page instead of Setting page.
    [From Build 48.10] [# 648355, 648561]
  • In the NetScaler MAS Infrastructure dashboard, NetScaler SD-WAN is not split into two instance types: SD-WAN WO and SD-WAN-EE. The SD-WAN displays include both SD-WAN WO and SD-WAN-EE instances.
    [From Build 48.10] [# 648690]
  • For a service pack with an auto-provisioned instance, NetScaler MAS does not support an HA pair for SDX.
    [From Build 48.10] [# 648566]
  • When a tenant assigned to a service package with an isolation policy partition is unable to create a VIP on a shared network, rollback fails and the NetScaler MAS displays the following error message: "Nitro timed out: Invalid Argument [tagged]." Although the rollback fails, configurations are successfully configured on the NetScaler instance type.
    [From Build 48.10] [# 648514]
  • On the Application dashboard, for all virtual servers, the Search criterion generates a wrong count even if the data displayed in the GUI is accurate.
    [From Build 48.10] [# 648441]
  • When the MAS receives a request from an OpenStack tenant, the name of the tenant does not appear in the Tenant Name field in on the Orchestration Request tab.
    [From Build 48.10] [# 637841]
  • When an HA pair is created with different NetScaler MAS versions, an erroneous "Invalid Password" message is displayed.
    [From Build 49.16] [# 647168]
Orchestration
  • In Orchestration, the Tasks page under the Request tab keeps refreshing even after the tasks are complete.
    [From Build 49.16] [# 647517]
  • After selecting one of the cloud platforms and submitting the form with the required settings under Orchestration, you are redirected to the Cloud Platform Selection page instead of the Deployment Settings page. With this fix, when you now select one of the cloud platforms and submit the form, you are redirected to the Deployment Settings page.
    [From Build 49.16] [# 648355, 648561]
  • For NSX Integration, a VLAN is allotted for every VXLAN during service insertion. The VLANs do not get de-allotted when service insertion is disabled/deleted. Because of this VLANs might get exhausted.
    [From Build 49.16] [# 648726]
  • During OpenStack orchestration, when you auto-provision a NetScaler VPX instance on NetScaler SDX in the NetScaler 11.1 release 48.10 build, an error is noticed during creation of the virtual IP address.
    [From Build 49.16] [# 655535]
  • In OpenStack integration, for an auto-provisioned NetScaler instance in NOVA, NetScaler MAS does not support a service package that specifies a partitioned isolation policy. Service package creation might succeed, but an error occurs when you configure the first load balancer.
    [From Build 49.16] [# 654374]
System
  • In NetScaler MAS, when you configure instance backup settings (System > Instance Backup Settings), the backup files are generated randomly and not at the set time interval. Also, the older backup files are not being deleted in the order that they were created.
    [From Build 49.16] [# 661153]
  • Earlier, when trying to remove or edit a threshold, the following error message appeared even for an nsroot user: "Not authorized to perform this operation." Now, you can remove or edit previously created thresholds on NetScaler MAS.
    [From Build 49.16] [# 654615]
  • Earlier, when trying to remove or edit a threshold, the following error message appeared even for an nsroot user: "Not authorized to perform this operation." Now, you can remove or edit previously created thresholds on NetScaler MAS.
    [From Build 50.10] [# 654615]
  • When multiple NetScaler MAS servers access a NetScaler instance at the same time to back up the instance, backup files might get overwritten. To prevent this, a random string is now appended to the backup files.
    [From Build 50.10] [# 658479]
Release history
For details of a specific release, see the corresponding release notes.

© 1999-2016 Citrix Systems, Inc. All rights reserved. | Terms of use.
Useful links

On this page

What's New? (35)
Fixed Issues (35)
Known Issues (22)
What's New in Previous 11.1 Builds (22)
Fixed Issues in Previous 11.1 Builds (44)